CVE-2023-29113 Details
Description
The MIB3 infotainment unit used in Skoda and Volkswagen vehicles does not incorporate any privilege separation for the proprietary inter-process communication mechanism, leaving attackers with presence in the system an ability to undermine access control restrictions implemented at the operating system level. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.
A vulnerability exists in the MIB3 infotainment units of Volkswagen and Skoda vehicles, specifically in models manufactured by Preh Car Connect GmbH. This vulnerability arises from the absence of privilege separation in the proprietary inter-process communication (IPC) mechanism used for remote procedure calls between services on the R-CAR M3 System-on-Chip. As a result, attackers with system presence can exploit this flaw to bypass access control restrictions at the operating system level. The vulnerability was confirmed in a Skoda Superb III vehicle with the MIB3 infotainment unit OEM part number 3V0035820, and it also affects various Volkswagen models with different OEM part numbers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 28, 2025CISA-ADP
Assessed Jun 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://asrg.io/security-advisories/vulnerabilities-in-volkswagen-mib3-infotainment-part-2/ | [email protected] | AdvisoryBundleTechnical Analysis |
| https://i.blackhat.com/EU-24/Presentations/EU-24-Parnishchev-OverTheAirVW.pdf | [email protected] | BundleTechnical Analysis |
| https://pcacybersecurity.com/resources/advisory/vulnerabilities-in-vw-mib3-infotainment-2 | [email protected] | AdvisoryBundleTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Volkswagen MIB3 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 28, 2025 | New CVE Received | [email protected] |
Volerion